Commit 61564b7c32

61564b7c32807deb349e28f2b5c6909cb4143870

parent: cabf60cf5b

Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-09-05 00:02 UTC

CHANGELOG: v1.13.2

Layout: unified · split

CHANGELOG.org +50
@@ -4,6 +4,56 @@ Versioning follows semver from v0.1.0. Database migrations run
4automatically on daemon start; upgrade notes appear per release when 4automatically on daemon start; upgrade notes appear per release when
5anything beyond "replace the binary and restart" is needed. 5anything beyond "replace the binary and restart" is needed.
6 6
7* v1.13.2 — 2026-09-04
8
9The first SonarCloud scan's findings: eight fixed, the rest triaged and
10dismissed with reasons.
11
12- A pages directory redirect could leave the site. Both redirects passed
13 the raw request path to =http.Redirect= while the cleaned path sat a
14 line above; =net/url= keeps a leading =//=, and Go emits
15 =Location: //evil.example/= unchanged, which a browser reads as
16 protocol-relative. Reaching it needed a public repository named like a
17 host under the subdomain's own owner — repository names permit dots —
18 so it was narrow rather than impossible. The destination is built from
19 the cleaned path through =url.URL= now, which also settles the two
20 spellings the first fix missed: a =..= that escapes to the root, and a
21 backslash, which browsers following the WHATWG rules treat as a
22 separator. #153
23- The runner's default workspace was =<tmp>/gitbay-runner=: a fixed name
24 in a world-writable directory, created with =MkdirAll=, which succeeds
25 against a directory whoever already owns it. bay1 was never exposed —
26 its unit names a workspace — but the default is what anyone running the
27 binary by hand gets, and this is the process that clones repositories
28 and exports build secrets. The default moves under the user's cache
29 directory, the workspace is created 0700, and a symlink or a directory
30 owned by someone else is refused. One we own that is merely too
31 permissive is tightened rather than refused, since every runner before
32 this one made it 0755 and refusing would take the runner down on
33 upgrade. #153
34- Logout and flash consumption expire their cookies with the attributes
35 the setting calls used. Deletion worked either way; the difference was
36 a reviewer's puzzle, and four findings. #153
37- The topics-remove field has a label. A placeholder is not an accessible
38 name. TestEveryInputHasAnAccessibleName is the guard that was missing,
39 and it knows both associations — six inputs use
40 =<label>Name <input></label>=, which is as good as for/id. #153
41- git and ssh are resolved once at start-up rather than searched on every
42 spawn, and gitbayd refuses to start when one is absent instead of
43 failing on whichever request first needed it. This was 74 of the 118
44 findings; a dashboard that is mostly permanent noise is one nobody
45 reads. #153
46
47Also: SQLite migrations are excluded from analysis. They were read as
48PL/SQL, where ='' is NULL=, so =WHERE col = ''= on a =NOT NULL DEFAULT ''=
49column — correct SQLite, and the shape used throughout — read as a
50null-comparison bug.
51
52Replace the binary and reinstall the CLI. No migration. A runner whose
53workspace is group- or world-readable will have it tightened to 0700 on
54next start, and will refuse to start if that workspace is a symlink or
55belongs to another user.
56
7* v1.13.1 — 2026-09-04 57* v1.13.1 — 2026-09-04
8 58
9A command that reads its payload from stdin says so, and SonarCloud runs 59A command that reads its payload from stdin says so, and SonarCloud runs